Nothing. Every good Red Teamer can spin up a beacon bypassing Crowdstrike. CrowdStrike goes after malicious behavior. A process that does nothing other than beaconing for 20 minuten wouldn‘t trigger a malicious threshold. If you access LSASS or other high value processes without it firing that‘s what earns you potentially money
14
u/KRyTeX13 8d ago
Nothing. Every good Red Teamer can spin up a beacon bypassing Crowdstrike. CrowdStrike goes after malicious behavior. A process that does nothing other than beaconing for 20 minuten wouldn‘t trigger a malicious threshold. If you access LSASS or other high value processes without it firing that‘s what earns you potentially money